As part of the Cyber Security Awareness Training I deliver, I always emphasise that any credentials people are entrusted with have a value and should be protected accordingly. Here is the proof of that statement – credentials for sale: ‘Russian Market’ emerges as a go-to shop for stolen credentials – …
Phishing attacks are not static
Time to add another chapter to my Phishing Email Primer: It is being reported that threat actors have been using a new targeting tactic to sort through victims who have been ensnared by their social engineering attacks. When presented with the malicious credentials Window, only those high-value victims who have …
To Catch A Thief… A Story of a Security Operations Centre
I am sorry, the title is a bit misleading, but once you have read the article, I am sure you will see how we – and the Security Operations Centre – could have caught a thief. Additionally, it is not about the Hitchcock movie; however, some of the action does …
Continue reading “To Catch A Thief… A Story of a Security Operations Centre”
Don’t Blame your Team – “Just Click Here”
Today we are talking About Links and here are a couple of questions to get us going on the topic: How realistic is the advice “don’t click on that link”? How many times in the day do you need to click on a link to do your work? Now I …
Continue reading “Don’t Blame your Team – “Just Click Here””
Signalgate
I am not sure anyone is actually calling it that… We have all seen and or heard of this story that is running in the US and around the world: Trump and intelligence chiefs play down Signal group chat leak – BBC News I am not going to get into …